Vulnerability record · CVE-2025-12507 · published 31 October 2025
CVE-2025-12507: Unquoted search path vulnerability
The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.
Description
The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References
Track CVE-2025-12507 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2025-12507), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.